[Git][security-tracker-team/security-tracker][master] 2 commits: Process two NFUs

Salvatore Bonaccorso carnil at debian.org
Tue Jan 26 20:14:49 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
432ae15b by Salvatore Bonaccorso at 2021-01-26T21:11:32+01:00
Process two NFUs

- - - - -
65758f1f by Salvatore Bonaccorso at 2021-01-26T21:14:26+01:00
Process more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -19,7 +19,7 @@ CVE-2021-3299
 CVE-2021-3298
 	RESERVED
 CVE-2021-3297 (On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to  ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2021-3296
 	RESERVED
 CVE-2021-3295
@@ -15559,7 +15559,7 @@ CVE-2020-35265
 CVE-2020-35264
 	RESERVED
 CVE-2020-35263 (EgavilanMedia User Registration & Login System 1.0 is affected by  ...)
-	TODO: check
+	NOT-FOR-US: EgavilanMedia User Registration & Login System
 CVE-2020-35262 (Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be e ...)
 	NOT-FOR-US: Digisol
 CVE-2020-35261
@@ -25988,13 +25988,13 @@ CVE-2020-27544
 CVE-2020-27543
 	RESERVED
 CVE-2020-27542 (Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection.  ...)
-	TODO: check
+	NOT-FOR-US: Rostelecom CS-C2SHW
 CVE-2020-27541 (Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. Agen ...)
-	TODO: check
+	NOT-FOR-US: Rostelecom CS-C2SHW
 CVE-2020-27540 (Bash injection vulnerability and bypass of signature verification in R ...)
-	TODO: check
+	NOT-FOR-US: Rostelecom CS-C2SHW
 CVE-2020-27539 (Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW ...)
-	TODO: check
+	NOT-FOR-US: Rostelecom CS-C2SHW
 CVE-2020-27538
 	RESERVED
 CVE-2020-27537
@@ -31559,7 +31559,7 @@ CVE-2020-25175 (GE Healthcare Imaging and Ultrasound Products may allow specific
 CVE-2020-25174 (A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3 ...)
 	NOT-FOR-US: B. Braun OnlineSuite Version AP
 CVE-2020-25173 (An attacker with local network access can obtain a fixed cryptography  ...)
-	TODO: check
+	NOT-FOR-US: Reolink P2P cameras
 CVE-2020-25172 (A relative path traversal attack in the B. Braun OnlineSuite Version A ...)
 	NOT-FOR-US: B. Braun OnlineSuite Version AP
 CVE-2020-25171
@@ -31567,7 +31567,7 @@ CVE-2020-25171
 CVE-2020-25170 (An Excel Macro Injection vulnerability exists in the export feature in ...)
 	NOT-FOR-US: B. Braun OnlineSuite Version AP
 CVE-2020-25169 (The affected Reolink P2P products do not sufficiently protect data tra ...)
-	TODO: check
+	NOT-FOR-US: Reolink P2P products
 CVE-2020-25168
 	RESERVED
 CVE-2020-25167
@@ -81105,7 +81105,7 @@ CVE-2020-4951
 CVE-2020-4950
 	RESERVED
 CVE-2020-4949 (IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2020-4948
 	RESERVED
 CVE-2020-4947
@@ -81225,7 +81225,7 @@ CVE-2020-4891
 CVE-2020-4890
 	RESERVED
 CVE-2020-4889 (IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2020-4888
 	RESERVED
 CVE-2020-4887 (IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d0dbf0967f524d95181ecfe10431793782e069cf...65758f1fba403d8d1c226203a16a0eb0a2636f48

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d0dbf0967f524d95181ecfe10431793782e069cf...65758f1fba403d8d1c226203a16a0eb0a2636f48
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210126/09562a5b/attachment.html>


More information about the debian-security-tracker-commits mailing list